[Git][security-tracker-team/security-tracker][master] CVE-2019-16723/cacti: upstream published a new fix
Hugo Lefeuvre
hle at debian.org
Sat Oct 19 14:37:22 BST 2019
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6f11ca68 by Hugo Lefeuvre at 2019-10-19T13:35:55Z
CVE-2019-16723/cacti: upstream published a new fix
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4512,10 +4512,12 @@ CVE-2019-16723 (In Cacti through 1.2.6, authenticated users may bypass authoriza
[jessie] - cacti <not-affected> (vulnerability introduced later)
NOTE: vulnerability introduced in
NOTE: https://github.com/Cacti/cacti/commit/cf73ae1a9f65b5a27d7f9d10c8e14835c3a76326
- NOTE: see Debian bug report for more explanations
+ NOTE: see Debian bug report for more information
NOTE: https://github.com/Cacti/cacti/issues/2964
NOTE: https://github.com/Cacti/cacti/commit/7a6a17252a1cbda180b61fff244cb3ce797d5264
NOTE: https://github.com/Cacti/cacti/commit/c7cf4a26e4848872b48094e67f8d0a01dd7613d2
+ NOTE: after further discussion, upstream issued a new fix which reverts previous commits
+ NOTE: https://github.com/Cacti/cacti/commit/cfb0733597af97abc92270de4f47cbfa32f9ce8b
NOTE: The original issue mentions only a bypass via graph_json.php but there are
NOTE: additional permission checks missed while checking the issue fixed with the
NOTE: upstream commits.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/6f11ca684174bef20adc6db080021b94089fc751
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/6f11ca684174bef20adc6db080021b94089fc751
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191019/ef685bdc/attachment.html>
More information about the debian-security-tracker-commits
mailing list